XSS through image upload of contacts using svg file

Disclosed: 2020-12-17 10:51:42 By hitman_47 To nextcloud
Low
Vulnerability Details
This is a bypass of report #808287 Upload the attached file for the image of a contact, right click "Open image in new tab" and you will see the xss. ## Impact The person viewing the image of a contact can be victim of XSS.
Actions
View on HackerOne
Report Stats
  • Report ID: 894876
  • State: Closed
  • Substate: resolved
  • Upvotes: 19
Share this report